Snort mailing list archives

Re: snort on router - risks?


From: Ravi <ravivsn () roc co in>
Date: Tue, 19 Aug 2003 09:29:56 +0530

Hi Edin,


 But if the guy only wants to use your IDS
machine for his own purposes he is not interested in breaking in your network.

If your packet filter with IDS onboard is being hacked, then much worse things
may happen.
I understand from your mail that snort is best deployed behind a firewall.
But one would be really intrested in a knowledge of attacks that commonly occur for his network from internet.

I think snort_inline is best suited for routers, but I agree the processing time it really takes.So go for high end routers with lots of memory.

Regards,
Ravi.



--


The views presented in this mail are completely mine. The company is not
responsible for whatsoever.
------------------------------------------------------------------------
Ravi Kumar CH
Rendezvous On Chip (i) Pvt Ltd
Hyderabad, India
Ph: +91-40-2335 1214 / 1175 / 1184

ROC home page <http://www.roc.co.in>





-------------------------------------------------------
This SF.Net email sponsored by: Free pre-built ASP.NET sites including
Data Reports, E-commerce, Portals, and Forums are available now.
Download today and enter to win an XBOX or Visual Studio .NET.
http://aspnet.click-url.com/go/psa00100003ave/direct;at.aspnet_072303_01/01
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: